Splunk Enterprise Security

How do enable Extreme Search command in ES App?

urbach
Explorer

After updating to ES App version 5.3.1, the extreme search commands no longer exist.

An error message is shown that the command is not found.

e.g.

Search: Access - Authentication Failures By Source - Context Gen

Unknown search command 'xsupdateddcontext'.

0 Karma

lkutch_splunk
Splunk Employee
Splunk Employee

The Splunk Machine Learning Toolkit (MLTK) replaced Extreme Search:
https://docs.splunk.com/Documentation/ES/6.1.1/Admin/MLTKoverview

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Extreme Search is not replaced until ES 6.0.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...

Uncovering Multi-Account Fraud with Splunk Banking Analytics

Last month, I met with a Senior Fraud Analyst at a nationally recognized bank to discuss their recent success ...

Secure Your Future: A Deep Dive into the Compliance and Security Enhancements for the ...

What has been announced?  In the blog, “Preparing your Splunk Environment for OpensSSL3,”we announced the ...